PT-2021-4529 · Pillow+9 · Pillow+9
Published
2021-02-28
·
Updated
2026-03-31
·
CVE-2021-25290
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Pillow versions prior to 8.1.1
Description
An issue was discovered in the TiffDecode.c component of the Pillow image processing library, related to a lack of memory volume check for reading, which can lead to a denial of service. The issue involves a negative-offset memcpy with an invalid size. This can be exploited by a remote attacker.
Recommendations
For versions prior to 8.1.1, update to version 8.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the TiffDecode.c component until a patch is available.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Pillow
Red Hat
Rocky Linux
Suse
Ubuntu